Data structure reconstruction method and device, electronic equipment and readable storage medium

Through the method of static analysis and structured rule knowledge base matching, the input data structure of UEFI firmware is reconstructed, solving the problem of limited reconstruction accuracy in the existing technology and achieving higher reconstruction accuracy.

CN120144554AActive Publication Date: 2025-06-13BEIJING UNIV OF POSTS & TELECOMM
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510200729.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-24
Publication Date
2025-06-13
Estimated Expiration
2045-02-24

AI Technical Summary

Technical Problem

When the prior art reverse reconstruction of the data structure of the input data of the UEFI firmware, the reconstruction accuracy is limited and cannot perfectly adapt to the characteristics of the UEFI firmware.

Method used

The initial data structure is initially reconstructed by the static analysis method of the UEFI firmware binary file, constructing a UEFI structured rule knowledge base, and matching the initial data structure with the structure definition in the knowledge base, and modifying the initial data structure using the matching target structure definition.

Benefits of technology

The data structure reconstruction accuracy of the input data of UEFI firmware is improved, so that the reconstructed data structure more accurately reflects the actual data structure of UEFI firmware.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120144554A_ABST
    Figure CN120144554A_ABST
Patent Text Reader

Abstract

The invention provides a data structure reconstruction method and device, electronic equipment and a readable storage medium, and the method comprises the steps: carrying out the static analysis of a UEFI firmware binary file, and preliminarily reconstructing an initial data structure of the input data of UEFI firmware; constructing a UEFI structured rule knowledge base; wherein the UEFI structured rule knowledge base comprises a plurality of structural body definitions; matching the initial data structure with each structure definition in a UEFI structured rule knowledge base, and determining a target structure definition with the highest matching degree from the UEFI structured rule knowledge base; and correcting the initial data structure by using a structure definition field in the target structure definition to obtain a target data structure of the input data of the reconstructed UEFI firmware. By means of the method, the reconstruction precision when the data structure of the input data of the UEFI firmware is reconstructed is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of binary reverse engineering and program analysis, and in particular, to a method, apparatus, electronic device, and readable storage medium for reconstructing a data structure. Background Art

[0002] UEFI (Unified Extensible Firmware Interface) firmware is the first software to run when a computer starts up, responsible for initializing hardware devices, loading driver programs when the computer starts up, and providing a stable startup environment for the operating system.

[0003] With the increasingly prominent core position of UEFI firmware in modern computer systems, the research on its security has become the focus of the industry. However, the data structure reverse reconstruction technology for the input data of UEFI firmware still faces significant challenges. Currently, the data structure reverse reconstruction of the input data of UEFI firmware mainly relies on traditional decompilation tools (which belong to static analysis tools). Since traditional decompilation tools are general-purpose tools and cannot perfectly adapt to the characteristics of UEFI firmware, the reconstruction accuracy is limited when using traditional decompilation tools (static analysis tools) to reconstruct the data structure of the input data of UEFI firmware. Summary of the Invention

[0004] In view of this, the purpose of the present application is to provide a method, apparatus, electronic device, and readable storage medium for reconstructing a data structure, so as to improve the reconstruction accuracy when reconstructing the data structure of the input data of UEFI firmware.

[0005] In a first aspect, an embodiment of the present application provides a method for reconstructing a data structure, including:

[0006] Performing static analysis on a UEFI firmware binary file through a static analysis method to initially reconstruct an initial data structure of the input data of the UEFI firmware;

[0007] Constructing a UEFI structured rule knowledge base; wherein, the UEFI structured rule knowledge base contains multiple structure definitions;

[0008] Matching the initial data structure with each of the structure definitions in the UEFI structured rule knowledge base, and determining a target structure definition with the highest matching degree from the UEFI structured rule knowledge base;

[0009] Using the structure definition fields in the target structure definition to correct the initial data structure to obtain a target data structure of the input data of the reconstructed UEFI firmware.

[0010] In combination with the first aspect, the embodiments of the present application provide a first possible implementation manner of the first aspect. Among them, the UEFI firmware binary file is statically analyzed by a static analysis method to initially reconstruct the initial data structure of the input data of the UEFI firmware, including:

[0011] Input the UEFI firmware binary file into the adjusted disassembly engine, and parse the UEFI firmware binary file through the disassembly engine to obtain the intermediate representation of the UEFI firmware; wherein, the disassembly engine is adjusted based on the data structure in the UEFI firmware binary file;

[0012] Based on the intermediate representation, determine the memory access instructions for each access object during the operation of the UEFI firmware; wherein, the memory access instructions contain multiple memory access fields; the memory access fields include the access object and offset corresponding to the memory access field, and the base address of the access object;

[0013] For each access object, by analyzing each memory access field in the memory access instructions of the access object, obtain the frequency of different offset access patterns and the different offset memory access fields for the same base address; wherein, the offset access pattern is determined based on the offset and number of bits of the memory access field; the offsets corresponding to different offset memory access fields are different;

[0014] For the different offset memory access fields with the same base address, determine the adjacent memory access fields belonging to the same structure, and initially reconstruct the initial data structure of the input data of the UEFI firmware corresponding to the access object according to the data access length of the access object corresponding to the base address.

[0015] In combination with the first possible implementation manner of the first aspect, the embodiments of the present application provide a second possible implementation manner of the first aspect. Among them, for the different offset memory access fields with the same base address, determine the adjacent memory access fields belonging to the same structure, and initially reconstruct the initial data structure of the input data of the UEFI firmware corresponding to the access object according to the data access length of the access object corresponding to the base address, including:

[0016] For the different offset memory access fields with the same base address, determine the adjacent memory access fields belonging to the same structure, and initially reconstruct the data structure to be adjusted of the input data of the UEFI firmware corresponding to the access object according to the data access length of the access object corresponding to the base address.

[0017] According to the frequencies of different offset access modes corresponding to the access object, select the offset access mode with the highest frequency, and adjust the number of bits of the data structure to be adjusted according to the number of bits corresponding to the offset access mode with the highest frequency, so as to obtain the initial data structure of the input data of the UEFI firmware corresponding to the access object.

[0018] Combined with the first possible implementation manner of the first aspect, the embodiments of the present application provide a third possible implementation manner of the first aspect, wherein building a UEFI structured rule knowledge base includes:

[0019] Extract header files from the open-source UEFI project, parse the structure definitions in the header files, and determine the offsets, field types, field bit numbers, compilation instructions, and type alignment rules of the respective structure definition fields included in the structure definitions;

[0020] For the processor architecture of each processor used to run the UEFI firmware, determine the default alignment rules of different processor architectures;

[0021] Determine the alignment constraints of the specified special structures in the UEFI firmware;

[0022] Based on the offsets, field types, field bit numbers, compilation instructions, and type alignment rules of the respective structure definition fields included in the structure definitions, as well as the default alignment rules of different processor architectures, and the alignment constraints of the specified special structures, build a UEFI structured rule knowledge base.

[0023] Combined with the third possible implementation manner of the first aspect, the embodiments of the present application provide a fourth possible implementation manner of the first aspect, wherein matching the initial data structure with each of the structure definitions in the UEFI structured rule knowledge base includes:

[0024] For each of the structure definitions in the UEFI structured rule knowledge base, calculate the similarity between the offsets of the fields in the initial data structure and the offsets of the respective structure definition fields in the structure definition, to obtain a similarity result;

[0025] Judge whether the lengths of the fields in the initial data structure match the lengths of the respective structure definition fields in the structure definition, to obtain a first judgment result;

[0026] Judge whether the initial data structure conforms to the memory alignment rules, to obtain a second judgment result; wherein, the memory alignment rules include the type alignment rules, the default alignment rules, and the alignment constraints;

[0027] Determine the matching degree between the initial data structure and the structure definition according to the similarity result, the first judgment result, and the second judgment result.

[0028] Combined with the fourth possible implementation manner of the first aspect, the embodiments of the present application provide a fifth possible implementation manner of the first aspect. Among them, the initial data structure is corrected by using the structure definition fields in the target structure definition to obtain the target data structure of the input data of the rebuilt UEFI firmware, including:

[0029] When the matching degree is greater than or equal to the first threshold, if the number of fields included in the initial data structure is less than the number of structure definition fields in the target structure definition, use the structure definition fields in the target structure definition to complement the missing fields in the initial data structure;

[0030] Correct the offsets in the fields included in the initial data structure by using the offsets in the structure definition fields in the target structure definition;

[0031] Complete the field types of each structure definition field in the target structure definition into each field in the initial data structure to obtain the target data structure of the input data of the rebuilt UEFI firmware.

[0032] Combined with the fifth possible implementation manner of the first aspect, the embodiments of the present application provide a sixth possible implementation manner of the first aspect. Among them, the initial data structure is corrected by using the structure definition fields in the target structure definition to obtain the target data structure of the input data of the rebuilt UEFI firmware, further including:

[0033] When the matching degree is greater than or equal to the second threshold and less than the first threshold, generate an artificial review suggestion and perform a special marking on the initial data structure; the first threshold is greater than the second threshold;

[0034] When the matching degree is less than the second threshold, trigger the optimization rule of the static analysis method to optimize the static analysis method.

[0035] In a second aspect, the embodiments of the present application further provide a data structure reconstruction device, including:

[0036] A reconstruction module, configured to perform static analysis on the UEFI firmware binary file through a static analysis method to initially reconstruct the initial data structure of the input data of the UEFI firmware;

[0037] A construction module, configured to construct a UEFI structured rule knowledge base; wherein, the UEFI structured rule knowledge base contains multiple structure definitions;

[0038] A matching module, configured to match the initial data structure with each of the structure definitions in the UEFI structured rule knowledge base, and determine a target structure definition with the highest matching degree from the UEFI structured rule knowledge base;

[0039] A correction module, configured to correct the initial data structure by using the structure definition fields in the target structure definition, so as to obtain a target data structure of the input data of the rebuilt UEFI firmware.

[0040] In a third aspect, an embodiment of the present application further provides an electronic device, including: a processor, a memory, and a bus. The memory stores machine-readable instructions executable by the processor. When the electronic device runs, the processor communicates with the memory through the bus. When the machine-readable instructions are executed by the processor, the steps in any possible implementation manner of the first aspect described above are executed.

[0041] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, the steps in any possible implementation manner of the first aspect described above are executed.

[0042] A data structure reconstruction method, apparatus, electronic device, and readable storage medium provided by an embodiment of the present application. After reconstructing the initial data structure of the input data of the UEFI firmware by using a static analysis method, the initial data structure is matched with each structure definition in the UEFI structured rule knowledge base, and a target structure definition with the highest matching degree is determined from the UEFI structured rule knowledge base; and the initial data structure is corrected by using the structure definition fields in the target structure definition, so that the obtained target data structure of the input data of the UEFI firmware is more accurate. It can be seen that through the reconstruction method of this embodiment, the reconstruction accuracy when reconstructing the data structure of the input data of the UEFI firmware can be improved.

[0043] In order to make the above objects, features, and advantages of the present application more obvious and understandable, the following specifically lists preferred embodiments and cooperates with the attached drawings to make a detailed description as follows. Description of the Drawings

[0044] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required to be used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0045] Figure 1Shows a flowchart of a data structure reconstruction method provided by an embodiment of the present application;

[0046] Figure 2 Shows a flowchart of another data structure reconstruction method provided by an embodiment of the present application;

[0047] Figure 3 Shows a schematic structural diagram of a data structure reconstruction device provided by an embodiment of the present application;

[0048] Figure 4 Shows a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0049] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, rather than all the embodiments. Usually, the components of the embodiments of the present application described and illustrated herein can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application to be protected, but merely represents the selected embodiments of the present application. All other embodiments obtained by those skilled in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0050] Considering that currently, the reverse reconstruction of the data structure of the input data of UEFI firmware mainly relies on traditional decompilation tools (which belong to static analysis tools). Since traditional decompilation tools are general-purpose tools and cannot perfectly adapt to the characteristics of UEFI firmware, the reconstruction accuracy is limited when using traditional decompilation tools (static analysis tools) to reconstruct the data structure of the input data of UEFI firmware. Based on this, the embodiments of the present application provide a data structure reconstruction method, device, electronic device, and readable storage medium to improve the reconstruction accuracy when reconstructing the data structure of the input data of UEFI firmware, which will be described below through embodiments.

[0051] To facilitate the understanding of this embodiment, a data structure reconstruction method disclosed in the embodiments of the present application will be introduced in detail first. As Figure 1 shown, it includes the following steps S101 - S104:

[0052] S101: Perform static analysis on the UEFI firmware binary file through the static analysis method to initially reconstruct the initial data structure of the input data of the UEFI firmware.

[0053] In this embodiment, a static structure reconstruction tool is used to perform static analysis on the UEFI firmware binary file, and the initial data structure of the input data of the UEFI firmware is initially reconstructed. Among them, the input data is the input of the UEFI firmware.

[0054] In a possible implementation manner, when performing step S101, as Figure 2 shown, it can be specifically executed according to the following steps S1011 - S1014:

[0055] S1011: Input the UEFI firmware binary file into the adjusted disassembly engine, and parse the UEFI firmware binary file through the disassembly engine to obtain the intermediate representation of the UEFI firmware; among them, the disassembly engine is adjusted based on the data structure in the UEFI firmware binary file.

[0056] In this embodiment, the UEFI firmware binary file is input into the adjusted disassembly engine, and the disassembly engine parses the UEFI firmware binary file by loading a predefined UEFI - specific ABI rule library to obtain the intermediate representation of the UEFI firmware;

[0057] Among them, since the disassembly engine is adjusted based on the data structure in the UEFI firmware binary file, the adjusted disassembly engine can more accurately parse the intermediate representation (IR, Intermediate Representation) of the UEFI firmware. The intermediate representation is a program representation form at an abstract level between high - level programming languages and machine code. It serves as an intermediate layer in the compiler chain for passing and processing code between different compilation stages.

[0058] S1012: Based on the intermediate representation, determine the memory access instructions for each access object during the operation of the UEFI firmware; among them, the memory access instructions contain multiple memory access fields; the memory access fields include the access object and offset corresponding to the memory access field, and the base address of the access object.

[0059] Exemplarily, the memory access instructions include: {mov[base address a + offset 1], access object A}, {mov[base address a + offset 2], access object A}, {mov[base address b + offset 1], access object B}, {mov[base address b + offset 2], access object B}, {mov[base address c + offset 2], access object C}. It can be seen that the memory access instructions in this example include five memory access fields. The base address is the access address of the access object.

[0060] S1013: For each access object, by analyzing each memory access field in the memory access instructions of the access object, obtain the frequencies of different offset access patterns and the memory access fields with different offsets for the same base address; wherein, the offset access pattern is determined based on the offset and number of bits of the memory access field; the offsets corresponding to different offset memory access fields are different.

[0061] Exemplarily, the number of bits is, for example, 16 bits or 32 bits. The memory access field with an offset of 1 and 32 bits corresponds to one offset access pattern; the memory access field with an offset of 2 and 32 bits corresponds to another offset access pattern; similarly, the memory access field with an offset of 2 and 16 bits also corresponds to other offset access patterns.

[0062] Continuing with the foregoing example, each memory access field corresponds to its own number of bits. If the number of bits corresponding to the memory access field {mov[base address a + offset 1], access object A} is 16 bits; the number of bits corresponding to the memory access field {mov[base address a + offset 2], access object A} is 16 bits; the number of bits corresponding to the memory access field {mov[base address b + offset 1], access object B} is 32 bits; the number of bits corresponding to the memory access field {mov[base address b + offset 2], access object B} is 32 bits; the number of bits corresponding to the memory access field {mov[base address a + offset 2], access object A} is 16 bits.

[0063] Then, in this example, the frequency of the offset access pattern (offset 1, 32 bits) is 1 / 5. The frequency of the offset access pattern (offset 1, 16 bits) is 1 / 5. The frequency of the offset access pattern (offset 2, 32 bits) is 1 / 5. The frequency of the offset access pattern (offset 2, 16 bits) is 2 / 5.

[0064] Moreover, in this example, the memory access fields with different offsets for the same base address a are: {mov[base address a + offset 1], access object A}, {mov[base address a + offset 2], access object A}, {mov[base address a + offset 2], access object A}.

[0065] The memory access fields with different offsets for the same base address b are: {mov[base address b + offset 1], access object B} and {mov[base address b + offset 2], access object B}.

[0066] S1014: For the memory access fields with different offsets for the same base address, determine the adjacent memory access fields belonging to the same structure, and initially reconstruct the initial data structure of the input data of the UEFI firmware corresponding to the access object according to the data access length of the access object corresponding to the base address.

[0067] Exemplarily, the data access length of the access object corresponding to the base address can be 16 bits or 32 bits. If the data access length of the access object corresponding to the base address a is 16 bits, then the data length of the initial data structure of the input data of the UEFI firmware corresponding to the initially reconstructed access object A is 16 bits.

[0068] In one possible implementation, when executing step S1014, it can be specifically executed according to the following steps S10141 - S10142:

[0069] S10141: For the memory access fields with different offsets corresponding to the same base address, determine the adjacent memory access fields belonging to the same structure, and initially reconstruct the data structure to be adjusted of the input data of the UEFI firmware corresponding to the access object according to the data access length of the access object corresponding to the base address.

[0070] S10142: According to the frequency of different offset access modes corresponding to the access object, select the offset access mode with the highest frequency, and adjust the number of bits of the data structure to be adjusted according to the number of bits corresponding to the offset access mode with the highest frequency, to obtain the initial data structure of the input data of the UEFI firmware corresponding to the access object.

[0071] Exemplarily, if the data access length of the access object A corresponding to the base address a is 16 bits, then the data length of the initially reconstructed data structure to be adjusted is 16 bits. From the example in the foregoing step S1013, among the frequencies of different offset access modes corresponding to the access object A, the offset access mode with the highest frequency is the offset access mode (offset 2, number of bits 16 bits). Then, at this time, there is no need to adjust the number of bits of the data structure to be adjusted.

[0072] Assume that among the frequencies of different offset access modes corresponding to the access object A, the offset access mode with the highest frequency is the offset access mode (offset 2, number of bits 32 bits). Then, the number of bits of the data structure to be adjusted can be adjusted according to 32 bits, so that the data length of the initial data structure of the input data of the UEFI firmware corresponding to the access object A obtained is 32 bits.

[0073] S102: Construct a UEFI structured rule knowledge base; where the UEFI structured rule knowledge base contains multiple structure definitions.

[0074] In this embodiment, each structure definition included in the UEFI structured rule knowledge base can be understood as a standard structure. The structure definition includes multiple structure definition fields, the offset of each structure definition field, and the number of bits of the structure definition field;

[0075] In a possible implementation, the UEFI structured rule knowledge base can be executed according to the following steps S1021 - S1024:

[0076] S1021: Extract header files from the open-source UEFI project, parse the structure definitions in the header files, and determine the offsets, field types, field bit widths, compilation directives, and type alignment rules of the respective structure definition fields included in the structure definitions.

[0077] S1022: For the processor architecture of each processor used to run the UEFI firmware, determine the default alignment rules for different processor architectures.

[0078] S1023: Determine the alignment constraints for the specified special structures in the UEFI firmware.

[0079] S1024: Based on the offsets, field types, field bit widths, compilation directives, and type alignment rules of the respective structure definition fields included in the structure definitions, as well as the default alignment rules for different processor architectures and the alignment constraints for the specified special structures, construct the UEFI structured rule knowledge base.

[0080] S103: Match the initial data structure with each structure definition in the UEFI structured rule knowledge base, and determine the target structure definition with the highest matching degree from the UEFI structured rule knowledge base.

[0081] In a possible implementation, when executing step S103, it can be specifically executed according to the following steps S1031 - S1034:

[0082] S1031: For each structure definition in the UEFI structured rule knowledge base, calculate the similarity between the offsets of the fields in the initial data structure and the offsets of the respective structure definition fields in this structure definition to obtain a similarity result;

[0083] S1032: Judge whether the lengths of the fields in the initial data structure match the lengths of the respective structure definition fields in this structure definition to obtain a first judgment result;

[0084] S1033: Judge whether the initial data structure conforms to the memory alignment rules to obtain a second judgment result; wherein, the memory alignment rules include type alignment rules, default alignment rules, and alignment constraints;

[0085] S1034: Determine the matching degree between the initial data structure and this structure definition according to the similarity result, the first judgment result, and the second judgment result.

[0086] In this embodiment, the similarity result is positively correlated with the matching degree. When the first judgment result is that the lengths of the fields in the initial data structure match the lengths of the structure definition fields in the structure definition, the higher the matching degree between the initial data structure and the structure definition; conversely, when the first judgment result is that the lengths of the fields in the initial data structure do not match the lengths of the structure definition fields in the structure definition, the lower the matching degree between the initial data structure and the structure definition.

[0087] Similarly, when the second judgment result conforms to the memory alignment rule, the higher the matching degree between the initial data structure and the structure definition; when the second judgment result does not conform to the memory alignment rule, the lower the matching degree between the initial data structure and the structure definition.

[0088] S104: Use the structure definition fields in the target structure definition to correct the initial data structure to obtain the target data structure of the input data of the rebuilt UEFI firmware.

[0089] In a possible implementation manner, when performing step S104, it can be specifically executed according to the following steps S1041 - S1043:

[0090] S1041: When the matching degree is greater than or equal to the first threshold (for example, 85%), if the number of fields included in the initial data structure is less than the number of structure definition fields in the target structure definition, use the structure definition fields in the target structure definition to complement the missing fields in the initial data structure.

[0091] Exemplarily, assume that the number of fields included in the initial data structure is 3, and the number of structure definition fields in the target structure definition is 5, then 2 missing fields in the initial data structure can be complemented with the structure definition fields in the target structure definition.

[0092] S1042: Use the offsets in the structure definition fields in the target structure definition to correct the offsets in the fields included in the initial data structure.

[0093] In this embodiment, for each field in the initial data structure, use the offset in the corresponding structure definition field in the target structure definition to correct the offset in this field.

[0094] S1043: Complement the field types of the structure definition fields in the target structure definition to the fields in the initial data structure to obtain the target data structure of the input data of the rebuilt UEFI firmware.

[0095] In the prior art, the field types of each field in the initial data structure are completed through manual marking. In this embodiment, through the method of automatic completion, it is beneficial to reduce the workload of manual labor.

[0096] In a possible implementation manner, when performing step S104, it can specifically be executed according to the following steps:

[0097] S1044: When the matching degree is greater than or equal to the second threshold (for example, 60%) and less than the first threshold (for example, 85%), generate a manual review suggestion and perform a special marking on the initial data structure; the first threshold is greater than the second threshold.

[0098] In this embodiment, the special marking can be to highlight and mark the initial data structure in yellow, etc., and the present application does not limit this.

[0099] S1045: When the matching degree is less than the second threshold, trigger the optimization rule of static analysis to optimize the static analysis.

[0100] In this embodiment, when the matching degree is less than the second threshold, trigger the optimization rule of the static structure reconstruction tool to optimize the static analysis. Use the optimized static structure reconstruction tool to re - reconstruct the initial data structure, which is the subsequent step.

[0101] Based on the same technical concept, the embodiment of the present application also provides a data structure reconstruction device, as Figure 3 shown, the device includes:

[0102] A reconstruction module 301, configured to perform static analysis on the UEFI firmware binary file through a static analysis method to preliminarily reconstruct the initial data structure of the input data of the UEFI firmware;

[0103] A construction module 302, configured to construct a UEFI structured rule knowledge base; wherein, the UEFI structured rule knowledge base contains multiple structure definitions;

[0104] A matching module 303, configured to match the initial data structure with each of the structure definitions in the UEFI structured rule knowledge base, and determine the target structure definition with the highest matching degree from the UEFI structured rule knowledge base;

[0105] A correction module 304, configured to correct the initial data structure by using the structure definition fields in the target structure definition to obtain the target data structure of the input data of the reconstructed UEFI firmware.

[0106] Optionally, when the reconstruction module 301 is used to statically analyze the UEFI firmware binary file by a static analysis method and initially reconstruct the initial data structure of the input data of the UEFI firmware, it is specifically used for:

[0107] Input the UEFI firmware binary file into the adjusted disassembly engine, and parse the UEFI firmware binary file through the disassembly engine to obtain the intermediate representation of the UEFI firmware; wherein, the disassembly engine is adjusted based on the data structure in the UEFI firmware binary file;

[0108] Based on the intermediate representation, determine the memory access instructions for each access object during the operation of the UEFI firmware; wherein, the memory access instructions include multiple memory access fields; the memory access fields include the access object and offset corresponding to the memory access field, and the base address of the access object;

[0109] For each access object, by analyzing each memory access field in the memory access instructions of the access object, obtain the frequency of different offset access patterns, and the memory access fields with different offsets for the same base address; wherein, the offset access pattern is determined based on the offset and number of bits of the memory access field; the offsets corresponding to different offset memory access fields are different;

[0110] For the memory access fields with different offsets for the same base address, determine the adjacent memory access fields belonging to the same structure, and initially reconstruct the initial data structure of the input data of the UEFI firmware corresponding to the access object according to the data access length of the access object corresponding to the base address.

[0111] Optionally, when the reconstruction module 301 is used to determine the adjacent memory access fields belonging to the same structure for the memory access fields with different offsets for the same base address, and initially reconstruct the initial data structure of the input data of the UEFI firmware corresponding to the access object according to the data access length of the access object corresponding to the base address, it is specifically used for:

[0112] For the memory access fields with different offsets for the same base address, determine the adjacent memory access fields belonging to the same structure, and initially reconstruct the data structure to be adjusted of the input data of the UEFI firmware corresponding to the access object according to the data access length of the access object corresponding to the base address.

[0113] According to the frequency of different offset access patterns corresponding to the access object, select the offset access pattern with the highest frequency, and adjust the number of bits of the data structure to be adjusted according to the number of bits corresponding to the offset access pattern with the highest frequency, to obtain the initial data structure of the input data of the UEFI firmware corresponding to the access object.

[0114] Optionally, when the building module 302 is used to build a UEFI structured rule knowledge base, it is specifically used for:

[0115] Extract header files from the open-source UEFI project, parse the structure definitions in the header files, and determine the offsets, field types, field bit widths, compilation instructions, and type alignment rules of the respective structure definition fields included in the structure definitions;

[0116] For the processor architecture of each processor used to run the UEFI firmware, determine the default alignment rules for different processor architectures;

[0117] Determine the alignment constraints of the specified special structures in the UEFI firmware;

[0118] Based on the offsets, field types, field bit widths, compilation instructions, and type alignment rules of the respective structure definition fields included in the structure definitions, as well as the default alignment rules for different processor architectures and the alignment constraints of the specified special structures, build a UEFI structured rule knowledge base.

[0119] Optionally, when the matching module 303 is used to match the initial data structure with each of the structure definitions in the UEFI structured rule knowledge base, it is specifically used for:

[0120] For each of the structure definitions in the UEFI structured rule knowledge base, calculate the similarity between the offsets of the fields in the initial data structure and the offsets of the respective structure definition fields in the structure definition to obtain a similarity result;

[0121] Judge whether the lengths of the fields in the initial data structure match the lengths of the respective structure definition fields in the structure definition to obtain a first judgment result;

[0122] Judge whether the initial data structure conforms to the memory alignment rules to obtain a second judgment result; wherein, the memory alignment rules include the type alignment rules, the default alignment rules, and the alignment constraints;

[0123] Based on the similarity result, the first judgment result, and the second judgment result, determine the matching degree between the initial data structure and the structure definition.

[0124] Optionally, when the correction module 304 is used to correct the initial data structure by using the structure definition fields in the target structure definition to obtain the target data structure of the input data of the rebuilt UEFI firmware, it is specifically used for:

[0125] When the matching degree is greater than or equal to the first threshold, if the number of fields included in the initial data structure is less than the number of structure definition fields in the target structure definition, the structure definition fields in the target structure definition are used to complement the missing fields in the initial data structure;

[0126] The offsets of the fields included in the initial data structure are corrected by using the offsets in the structure definition fields of the target structure definition;

[0127] The field types of the respective structure definition fields in the target structure definition are complemented to the respective fields in the initial data structure to obtain the target data structure of the input data of the rebuilt UEFI firmware.

[0128] Optionally, when the correction module 304 is used to correct the initial data structure by using the structure definition fields in the target structure definition to obtain the target data structure of the input data of the rebuilt UEFI firmware, it is further used for:

[0129] When the matching degree is greater than or equal to the second threshold and less than the first threshold, an artificial review suggestion is generated, and the initial data structure is specially marked; the first threshold is greater than the second threshold;

[0130] When the matching degree is less than the second threshold, the optimization rule of the static analysis method is triggered to optimize the static analysis method.

[0131] Figure 4 The structural schematic diagram of an electronic device provided by an embodiment of the present application includes: a processor 401, a memory 402, and a bus 403. The memory 402 stores machine-readable instructions executable by the processor 401. When the electronic device runs the above information processing method, the processor 401 communicates with the memory 402 through the bus 403, and the processor 401 executes the machine-readable instructions to execute the method steps in the first embodiment.

[0132] An embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, it executes the method steps in the first embodiment.

[0133] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described device, electronic device, and computer-readable storage medium can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.

[0134] In several embodiments provided by the present application, it should be understood that the disclosed methods, devices, electronic devices, and computer-readable storage media can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of modules is only a logical function division. In actual implementation, there may be other division methods. For another example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some communication interfaces. The indirect coupling or communication connection of devices or modules can be in electrical, mechanical, or other forms.

[0135] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0136] In addition, in each embodiment of the present application, each functional unit can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.

[0137] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a non-volatile computer-readable storage medium executable by a processor. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0138] Finally, it should be noted that the above embodiments are only specific implementation manners of the present application, used to illustrate the technical solutions of the present application, rather than limiting it. The protection scope of the present application is not limited thereto. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that any person skilled in the technical field can still modify the technical solutions recorded in the foregoing embodiments, or can easily think of changes, or perform equivalent replacements on some of the technical features; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A data structure reconstruction method, characterized in that: include: Static analysis is performed on the UEFI firmware binary file by using a static analysis method to preliminarily reconstruct the initial data structure of the input data of the UEFI firmware; Constructing a UEFI structured rule knowledge base; wherein the UEFI structured rule knowledge base includes a plurality of structure definitions; Matching the initial data structure with each of the structure definitions in the UEFI structured rule knowledge base, and determining a target structure definition with the highest matching degree from the UEFI structured rule knowledge base; The initial data structure is corrected using the structure definition fields in the target structure definition to obtain a target data structure of the reconstructed input data of the UEFI firmware.

2. The method according to claim 1, characterized in that: The UEFI firmware binary file is statically analyzed by static analysis methods to preliminarily reconstruct the initial data structure of the UEFI firmware input data, including: Inputting the UEFI firmware binary file into the adjusted disassembly engine, parsing the UEFI firmware binary file through the disassembly engine to obtain an intermediate representation of the UEFI firmware; wherein the disassembly engine is adjusted based on the data structure in the UEFI firmware binary file; Based on the intermediate representation, determining a memory access instruction for each access object during the running of the UEFI firmware; wherein the memory access instruction includes a plurality of memory access fields; the memory access field includes an access object and an offset corresponding to the memory access field, and a base address of the access object; For each of the access objects, by analyzing each memory access field in the memory access instruction of the access object, the frequency of different offset access modes and different offset memory access fields for the same base address are obtained; wherein the offset access mode is determined based on the offset and the number of bits of the memory access field; and different offset memory access fields correspond to different offsets; For memory access fields with different offsets of the same base address, adjacent memory access fields belonging to the same structure are determined, and based on the data access length of the access object corresponding to the base address, the initial data structure of the input data of the UEFI firmware corresponding to the access object is preliminarily reconstructed.

3. The method according to claim 2, characterized in that: For memory access fields with different offsets of the same base address, adjacent memory access fields belonging to the same structure are determined, and according to the data access length of the access object corresponding to the base address, an initial data structure of the input data of the UEFI firmware corresponding to the access object is preliminarily reconstructed, including: For memory access fields with different offsets of the same base address, adjacent memory access fields belonging to the same structure are determined, and based on the data access length of the access object corresponding to the base address, the data structure to be adjusted of the input data of the UEFI firmware corresponding to the access object is preliminarily reconstructed. According to the frequencies of different offset access modes corresponding to the access object, the offset access mode with the highest frequency is selected, and according to the number of bits corresponding to the offset access mode with the highest frequency, the number of bits of the data structure to be adjusted is adjusted to obtain the initial data structure of the input data of the UEFI firmware corresponding to the access object.

4. The method according to claim 2, characterized in that: Build a UEFI structured rule knowledge base, including: Extract a header file from an open source UEFI project, parse the structure definition in the header file, and determine the offset, field type, field bit number, compilation instructions, and type alignment rules of each structure definition field contained in the structure definition; For each processor architecture used to run the UEFI firmware, determining a default alignment rule for different processor architectures; Determining an alignment constraint for a specified special structure in the UEFI firmware; Based on the offset, field type, field bit number, compilation instructions and type alignment rules of each structure definition field contained in the structure definition, as well as the default alignment rules of different processor architectures and the alignment constraints of specified special structures, a UEFI structured rule knowledge base is constructed.

5. The method according to claim 4, characterized in that: Matching the initial data structure with each of the structure definitions in the UEFI structured rule knowledge base includes: For each of the structure definitions in the UEFI structured rule knowledge base, calculating the similarity between the offset of each field in the initial data structure and the offset of each structure definition field in the structure definition, to obtain a similarity result; Determine whether the length of each field in the initial data structure matches the length of each structure definition field in the structure definition, and obtain a first determination result; Determine whether the initial data structure complies with the memory alignment rule to obtain a second determination result; wherein the memory alignment rule includes the type alignment rule, the default alignment rule and the alignment constraint; The matching degree between the initial data structure and the structure definition is determined according to the similarity result, the first judgment result and the second judgment result.

6. The method according to claim 5, characterized in that: The initial data structure is modified by using the structure definition field in the target structure definition to obtain a target data structure of the input data of the reconstructed UEFI firmware, including: When the degree of match is greater than or equal to a first threshold, if the number of fields included in the initial data structure is less than the number of structure definition fields in the target structure definition, the structure definition fields in the target structure definition are used to complete the missing fields in the initial data structure; Correcting an offset in a field contained in the initial data structure using an offset in a structure definition field in the target structure definition; The field type of each structure definition field in the target structure definition is completed to each field in the initial data structure to obtain a target data structure of the reconstructed input data of the UEFI firmware.

7. The method according to claim 6, characterized in that: The initial data structure is corrected by using the structure definition field in the target structure definition to obtain a target data structure of the input data of the reconstructed UEFI firmware, further comprising: When the matching degree is greater than or equal to a second threshold and less than the first threshold, a manual review suggestion is generated, and the initial data structure is specially marked; the first threshold is greater than the second threshold; When the matching degree is less than the second threshold, the optimization rule of the static analysis method is triggered to optimize the static analysis method.

8. A data structure reconstruction device, characterized in that: The device comprises: A reconstruction module, used to perform static analysis on the UEFI firmware binary file by a static analysis method, and preliminarily reconstruct an initial data structure of input data of the UEFI firmware; A construction module, used to construct a UEFI structured rule knowledge base; wherein the UEFI structured rule knowledge base contains multiple structure definitions; A matching module, used for matching the initial data structure with each of the structure definitions in the UEFI structured rule knowledge base, and determining a target structure definition with the highest matching degree from the UEFI structured rule knowledge base; The correction module is used to correct the initial data structure by using the structure definition field in the target structure definition to obtain a target data structure of the input data of the reconstructed UEFI firmware.

9. An electronic device, characterized in that: include: A processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor. When the electronic device is running, the processor and the memory communicate via the bus, and when the machine-readable instructions are executed by the processor, the steps of any method as claimed in claim 1 to 7 are performed.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of any method according to claim 1 to 7 are executed.

Citation Information

Patent Citations

  • Matrix and vector manipulation to support machine learning reasoning and other processes

    CN115964598A

  • Code migration method and device, equipment and medium

    CN116954614A

  • Virtualization equipment configuration method and device, equipment and medium

    CN117009032A

  • UEFI firmware vulnerability detection method and device

    CN118070289A

  • Data processing method, electronic equipment and computer readable storage medium

    CN119248792A